Code Injection Flaw in yaojingang GEOFlow's Superadmin Theme Editor
CVE-2026-82666

5.1MEDIUM

Key Information:

Vendor

Yaojingang

Status
Vendor
CVE Published:
31 August 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-82666?

A code injection vulnerability exists in the Superadmin Theme Editor of yaojingang GEOFlow versions up to 2.1.0. This flaw allows an attacker to manipulate the function preview of the SiteThemeEditorController.php file, leading to potential remote code execution. The exploit is already publicly available, thus emphasizing the urgency for users operating the affected version to upgrade to at least version 2.1.1, where the issue has been patched. Immediate action is recommended to mitigate risks associated with this vulnerability.

Affected Version(s)

GEOFlow 2.0

GEOFlow 2.1.0

GEOFlow 2.1.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

iswangxy (VulDB User)
.